Fake antivirus peddlers helped by Microsoft

NormCameron

Vista Guru
"Just weeks after the U.S. Federal Trade Commission shut down two companies accused of selling fake antivirus software, a new player has moved into the market, aided by glitches in the Microsoft and U.S. Internal Revenue Service Web sites. Over the past four days the scammers have used so-called redirector links on Web sites belonging to magazines, universities and, most remarkably, the Microsoft.com and IRS.gov domains, said Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, who first reported the activity on his blog Tuesday.
Many Web sites use redirector links to take visitors away from the site, although the Web site operators try to stop them from being misused by scammers. For example, the Google URL http://www.google.com/search?q=idg&btnI=3564 uses Google's "I'm feeling lucky" feature to send Web surfers to IDG.com.
If criminals can use a redirector on a major Web site like Microsoft.com or IRS.gov, however, they can make their malicious links pop up very high in Google search results, Warner said in an interview.
"Microsoft is a super-powerful site as far as search engine weight is concerned," he said.
The bad guys have tricked search engines into returning their malicious links to tens of thousands of search terms, Warner said. They've done this by using special software to add these redirector links to "tens of thousands of blog comments, guestbook entries and imaginary blog stories all around the Internet," Warner said in his blog posting.
You can see the results of this activity. A Google search for the term "Microsoft Office 2002 download" yields a Microsoft.com redirection link as its first result. That link had been redirecting visitors to a malicious Web site, which launched Web-based attack code against victims and tried to trick them into downloading fake antivirus software, Warner said. By Tuesday evening, Microsoft had fixed the problem, so the Microsoft.com link that pops up in the Google search results was no longer taking surfers to the malicious Web site.
The IRS has now addressed the issue too, but about 20 other sites remain a problem, Warner said.
The fake antivirus software, also called "scareware," installs a keylogger on the victim's computer, presumably to steal log-in names and passwords, and also launches fake warning popups on every Web page that the victim visits telling him he needs to buy antivirus software, called System Security. The price for the fake product? A believable-sounding $51.45.
The FTC estimates that 1 million consumers were taken in by other fake antivirus products that go by names such as WinFixer, WinAntivirus, DriveCleaner, ErrorSafe and XP Antivirus. On Dec. 10, a federal court ordered two companies, Innovative Marketing and ByteHosting Internet Services, to stop promoting these products.
Warner doesn't know who is behind System Security, but he believes that the scammers behind this latest operation may be connected to the earlier scams. "It's similar enough that it's got to be somebody who has a relationship with the last group," he said"

Fake antivirus peddlers helped by Microsoft, IRS redirect glitches
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
Thanks for that Norm, very interesting reading.
Hope your day is going well ;)
 

My Computer

System One

  • Operating System
    Windows 10 Home
    Manufacturer/Model
    HP Envy x360 Convertible 15-bq0xx
    CPU
    AMD A9 Stoney Ridge Technology
    Motherboard
    HP 8312 (Socket FP4)
    Memory
    8.00GB Dual-Channel Unknown (?-0-0-0)
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) 512MB ATI AMD Radeon R5
    Sound Card
    AMD High Definition Audio Device Realtek High Definition Aud
    Monitor(s) Displays
    Generic PnP Monitor on AMD Radeon R5 Graphics
    Screen Resolution
    1920 x 1080
    Hard Drives
    119GB SanDisk SD8SN8U-128G-1006 (SSD)
    931GB Hitachi HGST HTS721010A9E630 (SATA
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft Optical Wheel Mouse
    Internet Speed
    62.86Mbps down 18.19Mbps up
    Other Info
    EPSON78D0CF (XP-332 335 Series) (Default Printer)
Thanks for that Norm, very interesting reading.
Hope your day is going well ;)
It was Joan, gone now, It's Boxing Day. And yours went well I trust?

Norm
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
Back
Top